{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-41049",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-07-12T12:17:45.625Z",
        "datePublished": "2024-07-29T14:32:05.953Z",
        "dateUpdated": "2026-08-05T11:35:00.349Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:35:00.349Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfilelock: fix potential use-after-free in posix_lock_inode\n\nLight Hsieh reported a KASAN UAF warning in trace_posix_lock_inode().\nThe request pointer had been changed earlier to point to a lock entry\nthat was added to the inode's list. However, before the tracepoint could\nfire, another task raced in and freed that lock.\n\nFix this by moving the tracepoint inside the spinlock, which should\nensure that this doesn't happen."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable `posix_lock_inode()` is reached from the local `fcntl(F_SETLK/F_SETLKW/F_OFD_SETLK)` syscall path (`fcntl_setlk` → `do_lock_file_wait` → `vfs_lock_file` → `posix_lock_file`), which is the universally present attack surface on every system. The nfsd/lockd/ksmbd callers of `vfs_lock_file()` also reach it, but those require an optional network file server to be configured and exporting a filesystem with no private `->lock`, so the core defect is characterized as local.\nAC:L - The attacker controls both sides of the race: one thread issues an overlapping same-type `F_SETLK` that merges into an existing lock (making `request` point at a list-resident lock), while a second attacker thread issues an overlapping `F_UNLCK`/`close()` that deletes and `kmem_cache_free()`s that entry, and the window between `spin_unlock(&ctx->flc_lock)`/`percpu_up_read()` and the tracepoint can be hit repeatedly in a tight loop with threads pinned to separate CPUs. Consistent with this CNA's scoring of other tracepoint-gated use-after-frees (CVE-2026-63910, CVE-2024-56759), the tracepoint-enabled precondition does not raise complexity.\nPR:L - Any unprivileged local user can call `fcntl()` on a file descriptor for a file it can already open; the only gate on the path is the `security_file_lock()` LSM hook, with no capability, root, or namespace requirement. POSIX advisory locks work on ordinary files in `/tmp`, `/dev/shm`, or the user's home directory.\nUI:N - The attacker's own threads perform every step — allocating the lock, merging it, and freeing it concurrently — with no action required from any other user or administrator.\nS:U - The freed `struct file_lock`, the corrupted read, and any resulting panic are all confined to the kernel of the same system; no VM, IOMMU, container, or sandbox boundary is crossed.\nC:H - The tracepoint reads seven fields out of a freed `filelock_cache` object — including the raw `flc_blocker` and `flc_owner` kernel pointers and the 64-bit `fl_start`/`fl_end` — after the attacker has had the opportunity to groom and reallocate that slab object, disclosing arbitrary reallocated kernel memory contents and defeating KASLR. Per kernel scoring guidance, use-after-free is rated High.\nI:H - A use-after-free on a `struct file_lock` that the attacker can reliably reallocate under control gives the classic UAF primitive — the stale `request` pointer is consumed as a live object after `kmem_cache_free()`, and heap spraying against the freed slot makes the condition exploitable for memory corruption rather than a benign stale read. Consistent with kernel guidance and this CNA's rating of the equivalent `dma_buf_fd()` tracepoint UAF, integrity impact is High.\nA:H - This is precisely the reported failure mode: the UAF read faulted the kernel on the reporter's MTE-enabled ARM64 system (`do_tag_check_fault` → `__do_kernel_fault` → panic), and on KASAN, hardware-tag, `slub_debug`, or `DEBUG_PAGEALLOC` builds the dereference of freed slab memory oopses. The race can be re-triggered in a loop, giving a repeatable local denial of service."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/locks.c"
                    ],
                    "versions": [
                        {
                            "version": "117fb80cd1e63c419c7a221ce070becb4bfc7b6d",
                            "lessThan": "1cbbb3d9475c403ebedc327490c7c2b991398197",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a6f4129378ca15f62cbdde09a7d3ccc35adcf49d",
                            "lessThan": "7d4c14f4b511fd4c0dc788084ae59b4656ace58b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "766e56faddbec2eaf70c9299e1c9ef74d846d32b",
                            "lessThan": "02a8964260756c70b20393ad4006948510ac9967",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "34bff6d850019e00001129d6de3aa4874c2cf471",
                            "lessThan": "5cb36e35bc10ea334810937990c2b9023dacb1b0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "74f6f5912693ce454384eaeec48705646a21c74f",
                            "lessThan": "432b06b69d1d354a171f7499141116536579eb6a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "74f6f5912693ce454384eaeec48705646a21c74f",
                            "lessThan": "116599f6a26906cf33f67975c59f0692ecf7e9b2",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "74f6f5912693ce454384eaeec48705646a21c74f",
                            "lessThan": "1b3ec4f7c03d4b07bad70697d7e2f4088d2cfe92",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e75396988bb9b3b90e6e8690604d0f566cea403a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5.4.257",
                            "lessThan": "5.4.280",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.197",
                            "lessThan": "5.10.222",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.133",
                            "lessThan": "5.15.163",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.55",
                            "lessThan": "6.1.100",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.5.5",
                            "lessThan": "6.6",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/locks.c"
                    ],
                    "versions": [
                        {
                            "version": "6.6",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.6",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.280",
                            "lessThanOrEqual": "5.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.222",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.163",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.100",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.41",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.9.10",
                            "lessThanOrEqual": "6.9.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.10",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4.257",
                                    "versionEndExcluding": "5.4.280"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10.197",
                                    "versionEndExcluding": "5.10.222"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15.133",
                                    "versionEndExcluding": "5.15.163"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.1.55",
                                    "versionEndExcluding": "6.1.100"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6",
                                    "versionEndExcluding": "6.6.41"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6",
                                    "versionEndExcluding": "6.9.10"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6",
                                    "versionEndExcluding": "6.10"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.5.5"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/1cbbb3d9475c403ebedc327490c7c2b991398197"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7d4c14f4b511fd4c0dc788084ae59b4656ace58b"
                },
                {
                    "url": "https://git.kernel.org/stable/c/02a8964260756c70b20393ad4006948510ac9967"
                },
                {
                    "url": "https://git.kernel.org/stable/c/5cb36e35bc10ea334810937990c2b9023dacb1b0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/432b06b69d1d354a171f7499141116536579eb6a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/116599f6a26906cf33f67975c59f0692ecf7e9b2"
                },
                {
                    "url": "https://git.kernel.org/stable/c/1b3ec4f7c03d4b07bad70697d7e2f4088d2cfe92"
                }
            ],
            "title": "filelock: fix potential use-after-free in posix_lock_inode",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://git.kernel.org/stable/c/1cbbb3d9475c403ebedc327490c7c2b991398197",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/7d4c14f4b511fd4c0dc788084ae59b4656ace58b",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/02a8964260756c70b20393ad4006948510ac9967",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/5cb36e35bc10ea334810937990c2b9023dacb1b0",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/432b06b69d1d354a171f7499141116536579eb6a",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/116599f6a26906cf33f67975c59f0692ecf7e9b2",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/1b3ec4f7c03d4b07bad70697d7e2f4088d2cfe92",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T21:59:49.896Z"
                }
            },
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-41049",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-09-10T16:22:47.848280Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-09-11T17:34:01.912Z"
                }
            }
        ]
    }
}